Headline
GHSA-967g-cjx4-h7j6: go-codec-dagpb vulnerable to panic when decoding invalid blocks
go-codec-dagpb is an implementation of the DAG-PB spec for Go. The dag-pb codec can panic when decoding invalid blocks. This issue has been patched in version 1.5.0.
go-codec-dagpb vulnerable to panic when decoding invalid blocks
High severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 29, 2022
Related news
CVE-2022-2584: fix: use protowire for Links bytes decoding · ipld/go-codec-dagpb@a17ace3
The dag-pb codec can panic when decoding invalid blocks.